Описание
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
Отчет
Red Hat has rated this issue as having an Impact of Important. This flaw is only exploitable when application code calls NLTK's downloader module (e.g. nltk.download()) to fetch corpora or model packages from the network at runtime, and an attacker is able to intercept or redirect that traffic via a man-in-the-middle position or DNS poisoning. Red Hat products that vendor nltk but do not invoke the downloader at runtime -- for example, images that ship pre-bundled NLTK data baked in at build time -- are not affected by this flaw regardless of the packaged nltk version.
Меры по смягчению последствий
Upgrade the nltk package to version 3.9.3 or later, which adds post-download integrity verification before extraction. Pin this minimum version in requirements files, lockfiles, and container image builds for all affected components. Where an immediate upgrade is not possible: avoid invoking NLTK's automatic downloader over untrusted or unauthenticated networks. Pre-download and independently verify the required NLTK data packages from a trusted source, host them in an internal, integrity-checked artifact repository, and point NLTK_DATA at that vetted local store so the runtime process never fetches data over the wire. Enforcing TLS with certificate validation and using trusted, DNSSEC-validated resolvers for the download endpoint reduces exposure to MITM/DNS-poisoning attacks but does not substitute for upgrading, since the underlying missing-integrity-check flaw remains present.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Under investigation | ||
| Lightspeed Core | lightspeed-core/lightspeed-stack-rhel9 | Not affected | ||
| Lightspeed Core | lightspeed-core/rag-tool-cpu-rhel9 | Not affected | ||
| Lightspeed Core | lightspeed-core/rag-tool-cuda-12.9-rhel9 | Not affected | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-ocp-rag-rhel9 | Not affected | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-service-api-rhel9 | Not affected | ||
| OpenShift Lightspeed | openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9 | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-chatbot-rhel8 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-llama-stack-core-rhel9 | Under investigation | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ogx-core-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
7.1 High
CVSS3
Связанные уязвимости
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
NLTK before 3.9.3 fails to verify file integrity after downloading pac ...
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
7.1 High
CVSS3